Jan Cholasta
83f6ddb473
makeapi: use the same formatting for int and long values
...
This prevents validation failures on architectures where integer is less
than 32 bits.
https://fedorahosted.org/freeipa/ticket/5894
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-05-19 16:43:58 +02:00
Jan Cholasta
5452006498
build: fix client-only build
...
https://fedorahosted.org/freeipa/ticket/5889
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-05-19 15:52:06 +02:00
Jan Cholasta
1276083d95
spec file: bump minimum required pki-core version
...
Require pki-core >= 10.2.6-19, which contains fixes for the following PKI
tickets:
* https://fedorahosted.org/pki/ticket/2022
* https://fedorahosted.org/pki/ticket/2247
* https://fedorahosted.org/pki/ticket/2255
https://fedorahosted.org/freeipa/ticket/5602
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2016-05-19 13:38:04 +02:00
Fraser Tweedale
356f262fb7
Detect and repair incorrect caIPAserviceCert config
...
A regression caused replica installation to replace the FreeIPA
version of caIPAserviceCert with the version shipped by Dogtag.
During upgrade, detect and repair occurrences of this problem.
Part of: https://fedorahosted.org/freeipa/ticket/5881
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-05-19 13:34:59 +02:00
Fraser Tweedale
5dad49688c
Prevent replica install from overwriting cert profiles
...
An earlier change that unconditionally triggers import of file-based
profiles to LDAP during server or replica install results in
replicas overwriting FreeIPA-managed profiles with profiles of the
same name shipped with Dogtag. ('caIPAserviceCert' is the affected
profile).
Avoid this situation by never overwriting existing profiles during
the LDAP import.
Fixes: https://fedorahosted.org/freeipa/ticket/5881
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-05-19 13:34:59 +02:00
Peter Lacko
144a367d35
Ping module tests.
...
Test for ping module rewritten using non-declarative way.
No new functionality has been added.
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-05-18 17:19:05 +02:00
Petr Spacek
89cdf6ee1e
Batch command: avoid accessing potentially undefined context.principal
...
This might happen when the command is called directly in Python,
e.g. in installers and so on.
Pylint pylint-1.5.5-1.fc24.noarch caught this.
https://fedorahosted.org/freeipa/ticket/5838
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-05-12 13:28:00 +02:00
Martin Basti
93332bcf4d
Remove unused variable and finally block in SchemaCache
...
Handling exceptions in python is expensive operation, removing of
uneeded finally block is good for performance.
Reviewed-By: Stanislav Laznicka <slaznick@redhat.com >
2016-05-12 11:18:40 +02:00
Martin Basti
ab2ebf489f
ipactl: advertise --ignore-service-failure option
...
For non-critical services which are failing may be beneficial for users
to ignore them and let IPA critical services start. For this a hint to
use --ignore-service-failue option should be shown.
https://fedorahosted.org/freeipa/ticket/5820
Reviewed-By: Stanislav Laznicka <slaznick@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2016-05-12 11:16:01 +02:00
Abhijeet Kasurde
2df25cb359
Added exception handling for mal-formatted XML Parsing
...
In order to handle mal-formatted XML returned from Dogtag, added
exception handling around etree.fromstring function.
https://fedorahosted.org/freeipa/ticket/5885
Signed-off-by: Abhijeet Kasurde <akasurde@redhat.com >
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-05-11 14:51:56 +02:00
Oleg Fayans
84e5065b39
Added necessary A record for the replica to root zone
...
A master can only be delegated a zone authority, if this zone contains A
records of the master and ALL replicas
https://fedorahosted.org/freeipa/ticket/5848
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-05-11 13:19:13 +02:00
Oleg Fayans
5567dff4b4
A workaround for ticket N 5348
...
A freshly created dnssec-enabled zone does not always display the signature
until you restart named-pkcs11. Added restarting of this service after each
dnssec-enabled zone.
https://fedorahosted.org/freeipa/ticket/5348
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-05-11 13:16:43 +02:00
Petr Spacek
ea794f3dec
Remove unused file install/share/fedora-ds.init.patch
...
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-05-11 09:57:05 +02:00
Petr Spacek
e345b53f35
DNS installer: accept --auto-forwarders option in unattended mode
...
https://fedorahosted.org/freeipa/ticket/5869
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-05-11 09:49:23 +02:00
Stanislav Laznicka
7098d98100
Fix to clean-dangling-ruv for single CA topologies
...
clean-dangling-ruv would fail in topologies with only one CA or
when only one IPA server is present
https://fedorahosted.org/freeipa/ticket/5840
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-05-10 17:31:25 +02:00
Gabe
bede6c282e
ipa-nis-manage enable: change service name from 'portmap' to 'rpcbind'
...
https://fedorahosted.org/freeipa/ticket/5857
Reviewed-By: Abhijeet Kasurde <akasurde@redhat.com >
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-05-10 16:30:03 +02:00
Abhijeet Kasurde
865935739a
Replaced find_hostname with api.env.host
...
Fixes: https://fedorahosted.org/freeipa/ticket/5841
Signed-off-by: Abhijeet Kasurde <akasurde@redhat.com >
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-05-10 13:12:54 +02:00
Petr Viktorin
7d4d819b90
test_cert_plugin: Encode 'certificate' for comparison with 'usercertificate'
...
The 'certificate' option is Str, but 'usercertificate' is Bytes.
Decode before comparing one with the other.
Part of the work for: https://fedorahosted.org/freeipa/ticket/4985
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-05-10 12:41:15 +02:00
Petr Viktorin
5dbb0f6fec
ipalib.cli: Improve reporting of binary values in the CLI
...
Make sure the base64-encoded value is a string, so it is printed
without the b'' markers.
Part of the work for: https://fedorahosted.org/freeipa/ticket/4985
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-05-10 12:41:15 +02:00
Petr Viktorin
a9a1353098
Fix remaining relative import and enable Pylint check
...
Relative imports are not supported in Python 3.
Part of the work for: https://fedorahosted.org/freeipa/ticket/4985
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-05-10 12:41:15 +02:00
Petr Spacek
475547fa40
DNS: Fix upgrade - master to forward zone transformation
...
This happens when upgrading from IPA <= 4.0 to versions 4.3+.
DNS caching might cause false positive in code which replaces master zone
with forward zone. This will effectivelly delete the master zone
without adding a replacement forward zone.
Solution is to use skip_overlap_check option for dnsforwardzone_add command
so zone existence check is skipped and the upgrade can proceed.
https://fedorahosted.org/freeipa/ticket/5851
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-05-10 10:13:56 +02:00
Abhijeet Kasurde
51db9380cf
Removed custom implementation of CalledProcessError
...
Removed custom class of CalledProcessError which was required for
Python versions prior to 2.5
Fixes: https://fedorahosted.org/freeipa/ticket/5717
Signed-off-by: Abhijeet Kasurde <akasurde@redhat.com >
Reviewed-By: Petr Spacek <pspacek@redhat.com >
2016-05-10 09:47:06 +02:00
Martin Basti
8787e03228
make: fail when ACI.txt or API.txt differs from values in source code
...
This regression was caused by commit 6acaf73b0c before this commit make rpms failed when API.txt did not match api
https://fedorahosted.org/freeipa/ticket/5865
Reviewed-By: Lukas Slebodnik <lslebodn@redhat.com >
2016-05-06 17:21:22 +02:00
Petr Viktorin
1ebd8334bc
Switch /usr/bin/ipa to Python 3
...
When building RPMs with Python 3 support, /usr/bin/ipa will now
use Python 3.
The in-tree ipa command will also run on Python 3.
When building with make install, $(PYTHON) is honored and it will
still default to Python 2.
Part of the work for https://fedorahosted.org/freeipa/ticket/5638
Reviewed-By: Petr Spacek <pspacek@redhat.com >
2016-05-06 16:17:28 +02:00
Tomas Babej
6adf863781
idviews: Add user certificate attribute to user ID overrides
...
https://fedorahosted.org/freeipa/ticket/4955
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-05-06 07:12:01 +02:00
Abhijeet Kasurde
42bcbcf460
Fix added to ipa-compat-manage command line help
...
Minor fix in ipa-compat-manage command help message.
Signed-off-by: Abhijeet Kasurde <akasurde@redhat.com >
Reviewed-By: Petr Spacek <pspacek@redhat.com >
2016-05-05 16:59:16 +02:00
Petr Viktorin
20a6a42567
test_add_remove_cert_cmd: Use bytes for base64.b64encode()
...
Part of the work for: https://fedorahosted.org/freeipa/ticket/4985
Reviewed-By: Martin Basti <mbasti@redhat.com >
Reviewed-By: Petr Spacek <pspacek@redhat.com >
2016-05-05 16:42:46 +02:00
Petr Viktorin
6ddf0d657f
certprofile plugin: Use binary mode for file with binary data
...
Part of the work for: https://fedorahosted.org/freeipa/ticket/4985
Reviewed-By: Martin Basti <mbasti@redhat.com >
Reviewed-By: Petr Spacek <pspacek@redhat.com >
2016-05-05 16:42:46 +02:00
Petr Viktorin
bdee890014
radiusproxy plugin tests: Expect bytes, not text, for ipatokenradiussecret
...
Part of the work for: https://fedorahosted.org/freeipa/ticket/4985
Reviewed-By: Martin Basti <mbasti@redhat.com >
Reviewed-By: Petr Spacek <pspacek@redhat.com >
2016-05-05 16:42:46 +02:00
Petr Viktorin
14aba1c7c1
range plugin tests: Use bytes with MockLDAP under Python 3
...
Part of the work for: https://fedorahosted.org/freeipa/ticket/4985
Reviewed-By: Martin Basti <mbasti@redhat.com >
Reviewed-By: Petr Spacek <pspacek@redhat.com >
2016-05-05 16:42:46 +02:00
Petr Viktorin
baaa041b8a
ipalib.rpc: Send base64-encoded data as string under Python 3
...
Python 3's JSON library cannot deal with bytes, so decode
base64-encoded data to string.
Part of the work for https://fedorahosted.org/freeipa/ticket/4985
Reviewed-By: Martin Basti <mbasti@redhat.com >
Reviewed-By: Petr Spacek <pspacek@redhat.com >
2016-05-05 16:42:46 +02:00
Petr Viktorin
095d0cb7af
xmlrpc_test: Expect bytes rather than strings for binary attributes
...
The attributes krbextradata, krbprincipalkey, and userpassword contain
binary data.
Part of the work for: https://fedorahosted.org/freeipa/ticket/4985
Reviewed-By: Martin Basti <mbasti@redhat.com >
Reviewed-By: Petr Spacek <pspacek@redhat.com >
2016-05-05 16:42:46 +02:00
Petr Viktorin
890f83b0bb
radiusproxy plugin: Use str(error) rather than error.message
...
In Python 3, the "message" attribute has been removed in favor of
calling str() on the error.
Part of the work for https://fedorahosted.org/freeipa/ticket/4985
Reviewed-By: Martin Basti <mbasti@redhat.com >
Reviewed-By: Petr Spacek <pspacek@redhat.com >
2016-05-05 16:42:46 +02:00
Petr Viktorin
6406c7a593
xmlrpc_test: Rename exception instance before working with it
...
Python 3 unsets the exception variable at the end of an "except"
block to prevent reference cycles and speed up garbage collection.
Store the exception under a different name in order to use it later.
Part of the work for https://fedorahosted.org/freeipa/ticket/4985
Reviewed-By: Martin Basti <mbasti@redhat.com >
Reviewed-By: Petr Spacek <pspacek@redhat.com >
2016-05-05 16:42:46 +02:00
Petr Viktorin
f753ad322d
test_xmlrpc: Use absolute imports
...
In Python 3, a module from the current package can be imported
either with the absolute name or by using an explicit relative import.
Part of the work for https://fedorahosted.org/freeipa/ticket/4985
Reviewed-By: Martin Basti <mbasti@redhat.com >
Reviewed-By: Petr Spacek <pspacek@redhat.com >
2016-05-05 16:42:46 +02:00
Martin Basti
b87a825d74
fix stageuser tests (removal of has_keytab and has_password from find)
...
User tests has been fixed, but stageuser tests was forgotten, this
commit fixes it.
https://fedorahosted.org/freeipa/ticket/5281
Reviewed-By: David Kupka <dkupka@redhat.com >
2016-05-05 15:20:19 +02:00
Abhijeet Kasurde
7d46fd15f8
Updated ipa command man page
...
Updated references and ipa command example in IPA man page
https://fedorahosted.org/freeipa/ticket/5871
Signed-off-by: Abhijeet Kasurde <akasurde@redhat.com >
Reviewed-By: Petr Spacek <pspacek@redhat.com >
2016-05-03 17:41:19 +02:00
Lenka Doudova
847c950408
Test fix: Cleanup for host certificate
...
This fix provides means to remove certificates from host that were added during tests, but not removed.
Ticket: https://fedorahosted.org/freeipa/ticket/5839
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-05-03 17:12:45 +02:00
Matt Rogers
8a2afcafee
ipa_kdb: add krbPrincipalAuthInd handling
...
Store and retrieve the authentication indicator "require_auth" string in
the krbPrincipalAuthInd attribute. Skip storing auth indicators to
krbExtraData.
https://fedorahosted.org/freeipa/ticket/5782
Reviewed-By: Sumit Bose <sbose@redhat.com >
2016-05-02 19:15:45 +02:00
Milan Kubík
829ba69e02
spec: Add python-sssdconfig dependency for python-ipatests package
...
https://fedorahosted.org/freeipa/ticket/5843
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2016-04-29 13:52:47 +02:00
Petr Spacek
037ee2a52c
ipa-nis-manage: mention return code 3 in man page
...
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-04-29 13:49:44 +02:00
Petr Spacek
f076dfc9d7
ipa-nis-manage: Replace text references to compat plugin with NIS
...
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-04-29 13:49:44 +02:00
Petr Spacek
51907d5bb8
Auto-detect default value for --forward-policy option in installers
...
Forward policy defaults to 'first' if no IP address belonging to a private
or reserved ranges is detected on local interfaces (RFC 6303).
Defaults to only if a private IP address is detected.
This prevents problems with BIND automatic empty zones because
conflicting zones cannot be disabled unless forwarding policy == only.
https://fedorahosted.org/freeipa/ticket/5710
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-04-28 18:46:06 +02:00
Petr Spacek
c7ee765c4d
Add function ipapython.dnsutil.inside_auto_empty_zone()
...
It allows to test if given DNS name belongs to an automatic empty zone.
https://fedorahosted.org/freeipa/ticket/5710
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-04-28 18:46:06 +02:00
Petr Spacek
1df30b4646
Use shared sanity check and tests ipapython.dnsutil.is_auto_empty_zone()
...
https://fedorahosted.org/freeipa/ticket/5710
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-04-28 18:46:06 +02:00
Petr Spacek
6752d6404a
Move function is_auto_empty_zone() into ipapython.dnsutil
...
I'm going to extend this so it is better to have it in module.
At the same time it is now using shared assert_absolute_dnsname()
helper.
https://fedorahosted.org/freeipa/ticket/5710
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-04-28 18:46:06 +02:00
Petr Spacek
41464b74f4
Add assert_absolute_dnsname() helper to ipapython.dnsutil
...
Sanity check for zone names and such should be the same everywhere.
This new function will be a replacement for ad-hoc checks.
https://fedorahosted.org/freeipa/ticket/5710
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-04-28 18:46:06 +02:00
Petr Spacek
bd32b48eb0
Move automatic empty zone list into ipapython.dnsutil and make it reusable
...
https://fedorahosted.org/freeipa/ticket/5710
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-04-28 18:46:06 +02:00
Petr Spacek
8997454889
Extend installers with --forward-policy option
...
This option specified forward policy for global forwarders.
The value is put inside /etc/named.conf.
https://fedorahosted.org/freeipa/ticket/5710
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-04-28 18:46:06 +02:00
Petr Spacek
9ee6d379c4
Remove function ipapython.ipautil.host_exists()
...
The function duplicated ipalib.util.verify_host_resolvable() in slightly
incompatible way because it used NSS while rest of IPA is using only DNS.
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-04-28 18:46:06 +02:00